Anthropic AI ban is now the settled position of the Pentagon, at least for the moment. On Friday 25 September 2026, a US appeals court upheld the Department of War’s decision to exclude Anthropic from its supply chain, a designation that followed the company’s refusal to remove two safeguards from its Claude models. The 2-1 ruling by the Court of Appeals for the District of Columbia Circuit leaves the exclusion in force, even though a federal court in California ruled last month that a broader government ban on Anthropic was illegal.
“US court sides with Pentagon in Anthropic AI ban” was how AFP put it, and the wording points at what the case is really about. The fight is not over price, performance or security flaws. It is over two lines Anthropic refused to cross: no fully autonomous lethal weapons, and no mass domestic surveillance of Americans. On the day the Anthropic AI ban was announced, OpenAI signed its own Pentagon deal and said that deal contained the same two principles.
Our detailed analysis of the D.C. Circuit’s Pentagon blacklisting ruling covers the statute, the majority’s reasoning and Judge Karen Henderson’s dissent. This article looks at the fight from the other side: the safeguards at its centre, how rivals kept similar red lines and still won contracts, what Anthropic, the Pentagon, the tech industry and legal experts said after Friday’s decision, and what the Anthropic AI ban now means for organisations buying AI and for the companies selling it.
Table of contents
- What the Court Decided About the Anthropic AI Ban
- The Two Safeguards Behind the Anthropic AI Ban
- Same Red Lines, No Ban: How Rivals Avoided the Anthropic AI Ban’s Fate
- Who Said What After the Anthropic AI Ban Ruling
- What the Anthropic AI Ban Covers After Friday
- What the Anthropic AI Ban Means for Businesses Buying AI
- What the Anthropic AI Ban Means for AI Vendors
- What Comes Next for the Anthropic AI Ban
- Frequently Asked Questions About the Anthropic AI Ban
- References
What the Court Decided About the Anthropic AI Ban
The panel split along the lines many lawyers expected. Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao. Judge Henderson dissented. The decision concerns only the designation made under the Federal Acquisition Supply Chain Security Act of 2018, which routes challenges straight to the D.C. Circuit.
The holding in one sentence
“The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk,” Katsas wrote. On the balance between that risk and the harm to Anthropic, he was blunt: “in our Republic, it is the President and the Secretary of War who must determine how best to balance” it.
Why the safeguards themselves counted against Anthropic
The majority did not say Anthropic’s safeguards were wrong. It said they showed Anthropic could shape how Claude behaves inside military systems. “As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent,” Katsas wrote. “On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users.” Anthropic said it cannot modify a model once delivered, but the court noted that the company decides how each new version behaves and the military must keep up with new versions. That reasoning reaches any supplier of AI models that ships refusals, not only Anthropic.
The dissent and the California split
Henderson rejected the idea that a law aimed at sabotage fits this case. “I cannot agree that this is the scenario the Congress had in mind when it enacted FASCSA,” she wrote. The ruling also sits beside the 27 August decision in the Northern District of California, which held that the broader Anthropic AI ban across federal agencies was unlawful. Breaking Defense summarised the split: the D.C. ruling “only covers the Defense Department ban”, while the California ruling against the government-wide ban is unaffected.
The Two Safeguards Behind the Anthropic AI Ban
Anthropic’s Claude usage policy allowed almost every military use the Pentagon asked for. The company said in February that it supported “all lawful uses of AI for national security aside from the two narrow exceptions” in dispute, and that “these exceptions have not affected a single government mission to date.” The Anthropic AI ban grew out of those two exceptions and nothing else.
Fully autonomous weapons
“We do not believe that today’s frontier AI models are reliable enough to be used in fully autonomous weapons,” Anthropic said. “Allowing current models to be used in this way would endanger America’s warfighters and civilians.” The objection is about reliability, not pacifism: Anthropic has sold Claude for defence and intelligence work through its Claude Gov models since 2025.
Mass domestic surveillance
The second line was a rights argument. “We believe that mass domestic surveillance of Americans constitutes a violation of fundamental rights,” Anthropic said. This was the safeguard with the widest public support, and the one that other AI companies were quickest to say they shared.
“All lawful purposes”
The Pentagon’s position was that a supplier cannot set conditions on a lawful military use. It has said it does not intend to use AI for mass domestic surveillance or fully autonomous weapons, and Under Secretary Emil Michael, the Pentagon’s chief technology officer, told CBS that federal law and Pentagon policy already bar those uses. What it refused was a vendor holding its own veto. Defense Secretary Pete Hegseth said the department “must have full, unrestricted access to Anthropic’s models for every LAWFUL purpose in defense of the Republic.”
The Maduro raid query
The court’s opinion adds one episode that explains the Pentagon’s alarm. According to AFP’s account of the decision, an Anthropic executive questioned the use of Claude by the contractor Palantir during the 3 January operation that captured Venezuelan president Nicolás Maduro. Michael said that objection “led to alarm” and “raised material doubts as to whether they would cause their software to stop working or cause some other disastrous action that would put our warfighters[‘] lives in danger.”
| Safeguard | Anthropic’s reason | Pentagon’s position |
|---|---|---|
| No fully autonomous weapons | Frontier models are not reliable enough and would endanger troops and civilians | Policy already requires human responsibility, so a vendor veto is unacceptable |
| No mass domestic surveillance | A violation of fundamental rights | Federal law already bars it, and the department decides lawful use |
| How it was enforced | Usage policy plus restrictions trained into Claude | Treated as a supplier able to make software “stop working” |
Same Red Lines, No Ban: How Rivals Avoided the Anthropic AI Ban's Fate
The most striking fact in the dispute is that Anthropic’s competitors say they hold the same values. They signed anyway, and the Anthropic AI ban shows why the form of a commitment can matter more than its content.
OpenAI’s deal on the same day
Hours after President Trump ordered agencies to stop using Anthropic on 27 February, OpenAI announced a deal to provide its models for classified networks. Sam Altman wrote that “two of our most important safety principles are prohibitions on domestic mass surveillance and human responsibility for the use of force, including for autonomous weapon systems. The DoW agrees with these principles, reflects them in law and policy, and we put them into our agreement.” Earlier that day he told CNBC these were “the few red lines” that “we share with Anthropic”.
xAI, Google, Microsoft and the rest
xAI was approved for classified settings in the same week, and AFP reports that it signed in February, with Google and Microsoft following a few months later. On 1 May, Reuters reported agreements with SpaceX, OpenAI, Google, Nvidia, Reflection AI, Microsoft and AWS to deploy AI on secret and top-secret networks. The Pentagon said the aim was to avoid “vendor lock”, and its GenAI.mil platform had reached more than 1.3 million personnel within five months.
| Company | When | What happened | Stated red lines |
|---|---|---|---|
| Anthropic | 27 Feb 2026 | Designated a supply chain risk | Autonomous weapons and domestic surveillance, enforced by contract and model |
| OpenAI | 27 Feb 2026 | Classified-network deal announced | The same two principles, “reflected in law and policy” |
| xAI | February 2026 | Approved for classified settings | Agreed to lawful use |
| Google, Microsoft, Nvidia, AWS, SpaceX, Reflection AI | 1 May 2026 | Secret and top-secret network agreements | Lawful operational use |
Policy versus product: why the difference mattered
The simplest reading of the record is that OpenAI accepted the government’s framing and Anthropic did not. OpenAI’s principles sit in its agreement and, in Altman’s words, are reflected in law and policy the department already follows. Anthropic wanted the right to enforce its limits itself, in the contract and in Claude’s behaviour. The court treated that second point as the risk. Under its reading, what matters is what a supplier can do to a system, not why it wants to.
The contract term at the heart of it
The Computer & Communications Industry Association, whose members include large technology companies, drew the same line in its statement. It noted that the court found the designation “was not based on Anthropic’s speech, but rather on the company’s refusal to revise a contract term.” For any vendor, that is the lesson of the Anthropic AI ban: a safeguard written as a unilateral right invites a fight that a safeguard written as shared policy does not.
Who Said What After the Anthropic AI Ban Ruling
Reaction came quickly and split along predictable lines. What is new is the tone. The Pentagon celebrated, the industry warned, and legal experts said the case is far from over.
Anthropic
“We respectfully disagree with the court’s decision. Another federal court has already held the government’s parallel designation unlawful. We remain confident in our position and are considering all options, including further review,” an Anthropic spokesperson said. The statement does not commit to a next step, but “further review” covers both the full D.C. Circuit and the Supreme Court.
The Pentagon
Michael took to X. “The hammer of justice has smashed Anthropic arguments,” he wrote, calling the company “a Supply Chain Risk to the defense industrial base” and adding that “warfighters will sleep better knowing that no private company will insert their opinions in the chain of command.” It was the same framing Hegseth used in February, when he accused Anthropic of trying to “seize veto power over the operational decisions of the United States military.”
The technology industry
CCIA, which joined ITI, SIIA and TechNet in amicus briefs in both courts, said the ruling “should alarm any government contractor”. Its statement continued: “Designating a company as a supply chain risk, a tool normally reserved for foreign adversaries, must be used with discretion and proper procedure — not as punishment for a company over a disagreement.” It warned that when firms see the government “arbitrarily penalize firms without proper process”, investment and competitiveness suffer.
Legal experts
Charlie Bullock of the Institute for Law & AI told Breaking Defense that the only routes left are an en banc rehearing or the Supreme Court, both discretionary. “This was the expected outcome, given the terrible luck Anthropic had with the panel draw,” he posted, adding: “I would expect Anthropic to win before an en banc DC Circuit and likely even before SCOTUS, but they’re not guaranteed any appeal at all.” Sean Timmons, a former military lawyer now at Tully Rinckey, said that “if a full panel is granted, all bets are off.”
The White House backdrop
AFP noted that Anthropic “has since become a pariah at the White House”, and that President Trump has called chief executive Dario Amodei’s warnings about AI risk a hoax. The civilian relationship is more complicated. Commerce Secretary Howard Lutnick said in early September that Anthropic was “back on the right side”, and government agencies have worked with Anthropic’s Mythos model on cybersecurity. The Anthropic AI ban is a Pentagon position, not a whole-of-government one.
| Who | Position after the ruling | Key words |
|---|---|---|
| Anthropic | Disagrees, weighing further review | “considering all options” |
| Pentagon (Emil Michael) | Vindicated | “The hammer of justice” |
| CCIA and co-amici | Alarmed for all contractors | “should alarm any government contractor” |
| Charlie Bullock | Expected loss, better odds higher up | “not guaranteed any appeal at all” |
| Sean Timmons | Full court could reverse | “all bets are off” |
What the Anthropic AI Ban Covers After Friday
The ruling is narrower than the headlines suggest. Breaking Defense put the scope precisely: the decision “allows the Pentagon to ban all use of Anthropic AI, not only by its own personnel, but also by private sector employees actively working on defense contracts.” It does not restore the wider measures the California court struck down.
Who is inside the Anthropic AI ban
Anthropic’s own reading, set out in February, is that a designation applies only to “the use of Claude as part of Department of War contracts—it cannot affect how contractors use Claude to serve other customers.” The government has acknowledged in court that the designation does not bar commercial use outside covered Department work. Our earlier analysis sets out the contract clauses and certification steps in detail, and the table below summarises who is affected.
| Who | Does the Anthropic AI ban apply? | Basis |
|---|---|---|
| Department of War staff and systems | Yes | Designation upheld on 25 September |
| Contractors, on Department of War work | Yes | Supply chain order enforced through contract clauses |
| Contractors, on commercial work | No, as now applied | Government’s position in court |
| Civilian federal agencies | Broader measures vacated | California ruling, 27 August |
| Businesses with no federal work | No | Neither designation reaches them |
Claude inside other products
The practical trap is indirect use. Claude reaches customers through Amazon Bedrock, Google Cloud’s Vertex AI and Microsoft’s Copilot, which now offers Anthropic’s Sonnet and Opus models as options, as we covered in our look at the new Microsoft Copilot. A defence contractor’s inventory has to include those routes, because a model picked inside another product is still Claude on covered work. Treat it as a compliance question with a named owner.
What the Anthropic AI Ban Means for Businesses Buying AI
Most organisations have no Pentagon contracts, and for them Friday’s ruling changes nothing directly. Claude remains fully available for commercial use. But the Anthropic AI ban exposes a risk that most AI procurement has ignored: a supplier’s values, and its disputes, can travel down the supply chain.
Vendor usage policies are now a procurement question
Every major AI company publishes a usage policy, and those policies differ. A vendor can refuse a use you need, and a vendor’s fight with a powerful customer can interrupt your supply. Neither risk appears in a typical model benchmark. Both belong in vendor management, alongside price, security and data residency.
Build for more than one model
The Pentagon’s own answer to vendor risk was to sign seven suppliers and avoid “vendor lock”. Businesses can do the same at smaller scale: keep prompts and integrations portable, test a second model on critical workflows, and avoid features that only one provider offers where a fallback matters. An AI strategy that assumes one provider forever is more fragile than it looks.
Do not overreact
Switching away from Claude because of the Anthropic AI ban would be a mistake for most buyers. The ruling concerns defence contracts, the commercial product is unchanged, and Anthropic’s business keeps expanding, including its recent $11.6 billion Akamai cloud deal. The sensible response is to document where each model is used and why, not to rip anything out.
| Organisation | Exposure | Sensible next step |
|---|---|---|
| Defence prime or subcontractor | Direct, on covered work | Inventory Claude use, including inside other products |
| Civilian government supplier | Limited after the California ruling | Follow the contracting officer’s written guidance |
| Regulated private business | Indirect, through vendor risk | Add usage policies to supplier due diligence |
| Small business using Claude | None today | Keep a second model tested for critical tasks |
What the Anthropic AI Ban Means for AI Vendors
For AI companies, the lesson is harder. The court’s reasoning means that the qualities Anthropic advertises, a model with firm refusals and a vendor that keeps improving it, are exactly what the Pentagon was allowed to treat as a risk.
Refusals are a feature and an exposure
A vendor that trains refusals into a model, and says so, has shown it can change how the product behaves. Under the D.C. Circuit’s reading, that ability alone can support a designation if the department needs uses the vendor will not allow. Any AI company selling to government should expect its usage policy to be read as a statement of control, not just of values.
The IPO question
The Anthropic AI ban also lands at an awkward moment for Anthropic’s finances. AFP describes the company as “valued at nearly one trillion dollars” and heading for “a blockbuster IPO expected in weeks”. In February, NPR put its valuation at $380 billion with $14 billion in revenue, against a Pentagon contract worth up to $200 million. The contract is small; the precedent is not. We examined the governance side of the listing in our piece on Anthropic’s founder voting control.
The chilling effect
CCIA’s warning is about everyone else. If a supply chain designation can follow a contract dispute with a domestic supplier, other vendors will think twice before insisting on safeguards the government dislikes. That may be the most lasting effect of the Anthropic AI ban: not a change in what AI companies believe, but in what they are willing to write into a contract.
What Comes Next for the Anthropic AI Ban
The ruling is not final in the practical sense. Anthropic has two paths to overturn it, the government has an open appeal option in California, and Congress could narrow the statute. All of them take months.
Rehearing by the full D.C. Circuit
Because the United States is a party, Anthropic has 45 days from the judgment to ask all active D.C. Circuit judges to rehear the case, which runs to Monday 9 November. Timmons pointed out that the full court, with judges appointed by four presidents, is harder to predict than the three-judge panel, and argued that the case is high-profile enough for the court to feel it must act.
The Supreme Court
A petition for certiorari is due within 90 days of the judgment, which would be Thursday 24 December, or within 90 days of any order denying rehearing. The Supreme Court takes only a small share of the cases it is asked to hear. Bullock’s view is that Anthropic would likely win there, but only if the Court agrees to hear it.
California, Congress and the Pentagon itself
The government may still appeal the California ruling to the Ninth Circuit. Congress could amend the 2018 Act to require a foreign link or bad intent, as Henderson’s dissent implies it was meant to. And the department could rescind the designation at any time. None of these has been reported as imminent.
Frequently Asked Questions About the Anthropic AI Ban
What is the Anthropic AI ban?
It is the Pentagon’s designation of Anthropic as a supply chain risk, announced on 27 February 2026 and formalised in March, after Anthropic refused to drop two limits on military use of Claude. It bars use of Claude by the Department of War and by contractors on Department of War work.
Did the court say Anthropic’s safeguards were wrong?
No. The majority did not judge the merits of the safeguards. It held that the Pentagon had enough support to treat a supplier that encodes restrictions into its model, and controls future versions, as a national security risk under the 2018 supply chain law.
Can businesses still use Claude?
Yes. The Anthropic AI ban as now applied covers Department of War systems and contractors’ work on Department of War contracts. Commercial use is unaffected, and a California court has vacated the broader measures aimed at civilian agencies and companies doing business with the military.
Why did OpenAI get a Pentagon deal with similar red lines?
OpenAI says its agreement includes prohibitions on domestic mass surveillance and human responsibility for the use of force. The difference is form: OpenAI accepted that the department reflects those principles in its own law and policy, while Anthropic insisted on enforcing its limits itself.
Is the ruling final?
Not yet. Anthropic can seek rehearing by the full D.C. Circuit by 9 November or petition the Supreme Court within 90 days. Both courts have discretion to refuse. Until then, the designation stays in effect.
How does the Anthropic AI ban affect Anthropic’s IPO?
It becomes a disclosed risk rather than a pending question. Any prospectus will need to explain that one federal court called the government’s measures unlawful while another upheld the Pentagon’s exclusion. Defence revenue is a small share of Anthropic’s business, but the precedent will interest investors.
References
AFP via Free Malaysia Today: US court sides with Pentagon in Anthropic AI ban
D.C. Circuit opinion, 25 September 2026 (Katsas, J.; Henderson, J., dissenting)
Breaking Defense: DC Circuit panel upholds Pentagon’s ban on Anthropic, so what comes next?
CCIA: Tech industry concerned by DC court ruling in Pentagon Anthropic dispute
NPR: OpenAI announces Pentagon deal after Trump bans Anthropic
Slashdot (Reuters): Pentagon reaches agreements with top AI companies, but not Anthropic
Anthropic PBC v. U.S. Department of War, No. 26-cv-01996 (N.D. Cal.), order of final relief
41 U.S.C. § 4713: Authorities relating to mitigating supply chain risks
CNBC: U.S. appeals court upholds Pentagon designation of Anthropic as supply chain risk
Mayer Brown: DoW’s Anthropic ban goes live, a confusing patchwork of certification demands
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.